Threat group.View on attack.mitre.org
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1036 Masquerading |
LazyScripter has used several different security software icons to disguise executables. |
| T1059.001 PowerShell |
LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.003 Windows Command Shell |
LazyScripter has used batch files to deploy open-source and multi-stage RATs. |
| T1059.005 Visual Basic |
LazyScripter has used VBScript to execute malicious code. |
| T1059.007 JavaScript |
LazyScripter has used JavaScript in its attacks. |
| T1071.004 DNS |
LazyScripter has leveraged dynamic DNS providers for C2 communications. |
| T1102 Web Service |
LazyScripter has used GitHub to host its payloads to operate spam campaigns. |
| T1105 Ingress Tool Transfer |
LazyScripter had downloaded additional tools to a compromised host. |
| T1204.001 Malicious Link |
LazyScripter has relied upon users clicking on links to malicious files. |
| T1204.002 Malicious File |
LazyScripter has lured users to open malicious email attachments. |
| T1218.005 Mshta |
LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.011 Rundll32 |
LazyScripter has used `rundll32.exe` to execute Koadic stagers. |
| T1547.001 Registry Run Keys / Startup Folder |
LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key. |
| T1566.001 Spearphishing Attachment |
LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.